Security

LG Uplus’s 15-Year Use of IMSI Linked to Phone Numbers Draws Fire Over Alleged Cover-Up of Hack

TECHWORLD ·

An image expressing the LG Uplus security controversy, including phone number-based IMSI management and allegations of concealing a security incident. [Photo: ChatGPT]

✦ AI Summary

At the National Assembly’s Science, ICT, Broadcasting and Communications Committee audit, LG Uplus’s IMSI management method that incorporates phone numbers and its response to last year’s security incident became key issues.

Rep. Cho Kyoung-tae pointed to the security of the IMSI structure and the risk of personal information exposure through an IMSI catcher, calling for the government to conduct empirical verification.

LG Uplus disposed of one compromised server and reinstalled the OS on another, and a public-private joint investigation said these steps made it impossible to identify the intrusion route and scope.

At the National Assembly’s Science, ICT, Broadcasting and Communications Committee audit, LG Uplus’s IMSI management method and its response to last year’s security incident emerged as key issues. Rep. Cho Kyoung-tae raised concerns on the 6th during the audit of the Ministry of Science and ICT and its affiliated agencies, pointing to LG Uplus’s long-term use of IMSIs that incorporate phone numbers.

An IMSI is a 15-digit identification number assigned by a mobile carrier to distinguish subscribers, and it is stored on a USIM. According to Rep. Cho’s office, the three major mobile carriers use different structures for the final digits of IMSIs, while LG Uplus used a method that reflects the subscriber’s phone number after the carrier code. LG Uplus has operated an IMSI structure incorporating phone numbers for about 15 years.

At the audit, the security of that structure became a point of contention. The impact of server disposal and OS reinstallation after last year’s security incident on the investigation was also debated. The discussion linked the security of the long-running IMSI structure incorporating phone numbers with the effect that server disposal and OS reinstallation had on the investigation after the incident.

Accordingly, lawmakers called for a review of the government’s oversight responsibility and the preparation of user protection measures. Rep. Cho argued that if police investigations into allegations of a cover-up of last year’s security incident confirm intent, users should be exempted from cancellation fees.

Cho pointed out that in this structure, the ease with which an IMSI and a phone number could be linked may increase the risk of personal information exposure. He raised concerns that an 'IMSI catcher' can operate as a fake base station and collect IMSIs from nearby devices, and said it could also be implemented using software-defined radio equipment (SDR) and open-source code. He also cited an actual demonstration case.

In April, an anonymous security researcher demonstrated collecting IMSIs from nearby LG Uplus devices using a homemade IMSI catcher. In that demonstration, the researcher confirmed the phone number and then even placed a call to that number, and related video footage was also made public. Cho argued that if phone numbers of subscribers at a specific location are collected, they could be abused for targeted smishing or location tracking, so the government should verify this directly.

Cho also challenged the government’s earlier judgment. In an answer at a full committee meeting of the committee in March, Deputy Prime Minister and Science and ICT Minister Bae Kyung-hoon said that operating IMSIs based on phone numbers was not a legal violation and that the possibility of secondary harm was very low. In response, Cho asked when the government became aware of that structure, what basis it had for judging the risk of secondary harm to be low, and whether it had conducted empirical checks on the use of IMSI catchers.

LG Uplus’s response to last year’s security incident also came under scrutiny. After receiving guidance from the Korea Internet & Security Agency (KISA) regarding hacking, LG Uplus disposed of one affected server, and after the Ministry of Science and ICT requested an internal inspection, it reinstalled the OS on another compromised server. Cho said these actions made it difficult to identify the intrusion route and the scope of the damage.

A public-private joint investigation later confirmed that the leaked data was indeed valid. However, the investigation concluded that the intrusion route and scope could not be identified because of the server disposal and OS reinstallation. In other words, the measures taken during the initial response created limitations in later determining the route and scope of the intrusion and leak.

The Ministry of Science and ICT referred LG Uplus to police on suspicion of 'obstruction of official duties by deceptive means,' citing issues with its response, and the Personal Information Protection Commission also referred the case for investigation on the same charge. Cho said that if police investigations confirm intentional concealment and interference with the probe, user protection measures are needed. He also pointed out that LG Uplus’s terms of service include a clause exempting users from paying cancellation fees when services are terminated due to the company’s fault, and argued that depending on the investigation results, the company should also consider whether to waive cancellation fees for all subscribers.

Cho said the government needs to conduct direct empirical checks and that user protection measures should be prepared as soon as possible. He added that if the police investigation confirms intentional concealment, appropriate measures such as waiving cancellation fees for all subscribers are necessary.

Democratic Party lawmaker Lee Hoon-ki stressed corporate responsibility for hacking and personal data leaks during the audit that day. He pointed to allegations that LG Uplus covered up the security incident and raised the issue of Tving leaving security vulnerabilities unaddressed. He also highlighted companies’ responsibility for security management and user protection after incidents.

Source: TECHWORLD · Kim Seung-gi
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407817

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.